Chain Reaction Transaction Extraction?

UndercoverElephant
UndercoverElephant Posts: 5,796
edited May 2011 in Commuting chat
Bad news....

http://www.theregister.co.uk/2011/03/17 ... purchases/
A security breach at popular UK-based biking site chainreactioncycles.com has been linked by victims to multiple instances of fraud.

Various bike enthusiast forums are alive with complaints (here and here) from customers of the site, several of whom are reporting unauthorised charges on their credit or debit cards. The majority of fraudulent transactions reported seem to involve mobile phone top-ups to either Vodafone or O2, typically two transactions valued at £15 or so for a total fraudulent amount of £30. However, a small percentage of victims have been taken for thousands of pounds.

Comments

  • Gazzaputt
    Gazzaputt Posts: 3,227
    Ouch
  • clarkey cat
    clarkey cat Posts: 3,641
    just claim the money back from your bank - they are required to refund you in law.

    The Payment Services Regulations 2009 if you really must know.
  • jonginge
    jonginge Posts: 5,945
    Yeah, my card got used fraudulently last year shortly after a purchase (my first with CRC). It may have been them or another purchase but, hey, I've not used them again
    FCN 2-4 "Shut up legs", Jens Voigt
    Planet-x Scott
    Rides
  • Duffer65
    Duffer65 Posts: 341
    A week or so ago I checked my account only to find out from my bank that someone had spent £420 of my money on a phone(?) via my debit card at a V store, Vodafone apparently. My bank cancelled the transaction and I wasn't left out of pocket. I wondered where the fraud originated from, now I know! Having bought some bike parts from them recently:x
    Where would you be if you fell down a hole?.. Stuck down a hole... in the fog... Stuck down a hole, in the fog, at night... WITH AN OWL!
  • tailwindhome
    tailwindhome Posts: 19,354
    There's a long thread about this in the MTB section

    The Register seems to be reporting on Internet Forum speculation rather than having any facts to report

    That said, I'm off to check my bank account.......
    “New York has the haircuts, London has the trousers, but Belfast has the reason!
  • Clever Pun
    Clever Pun Posts: 6,778
    just bought some chains from there... *rushes off to check* it's ok it's through paypal.. all safe...for now
    Purveyor of sonic doom

    Very Hairy Roadie - FCN 4
    Fixed Pista- FCN 5
    Beared Bromptonite - FCN 14
  • cee
    cee Posts: 4,553
    The Register seems to be reporting on Internet Forum speculation rather than having any facts to report

    No................a quality news outlet (pffft) like El Reg? Don't get me wrong, The Register can be amusing, but not exactly the place anyone decent in IT gets their news (unless that news is about Paris Hilton...then the reg is great!)
    Whenever I see an adult on a bicycle, I believe in the future of the human race.

    H.G. Wells.
  • nicklouse
    nicklouse Posts: 50,675
    "Do not follow where the path may lead, Go instead where there is no path, and Leave a Trail."
    Parktools :?:SheldonBrown
  • Gazzaputt
    Gazzaputt Posts: 3,227
    Only use Paypal on CRC and Wiggle these days.
  • The Rookie
    The Rookie Posts: 27,812
    Damn, it happened to me and I've never used my card with CRC, better use them quick so I can blame them.......

    Simon
    Currently riding a Whyte T130C, X0 drivetrain, Magura Trail brakes converted to mixed wheel size (homebuilt wheels) with 140mm Fox 34 Rhythm and RP23 suspension. 12.2Kg.
  • EKE_38BPM
    EKE_38BPM Posts: 5,821
    Damn, it happened to me and I've never used my card with CRC, better use them quick so I can blame them.......

    Simon

    No, no, no. Blame Wiggle!
    FCN 3: Raleigh Record Ace fixie-to be resurrected sometime in the future
    FCN 4: Planet X Schmaffenschmack 2- workhorse
    FCN 9: B Twin Vitamin - winter commuter/loan bike for trainees

    I'm hungry. I'm always hungry!
  • nich
    nich Posts: 888
    Gazzaputt wrote:
    Only use Paypal on CRC and Wiggle these days.

    Sorry to go off topic, but I've also started using paypal recently (for ebay!).

    Any idea what protection there is if someone hijacks your paypal account? - once in they would effectively have access to my bank account, which scares me a little :)
  • ADonmall
    ADonmall Posts: 12
    I use CRC quite a lot and late last year had a £30 fraudulent transaction for O2 Prepay. Bank refunded, but it would seem it came via CRC. Will think twice about buying from them again.
  • dhope
    dhope Posts: 6,699
    nich wrote:
    Gazzaputt wrote:
    Only use Paypal on CRC and Wiggle these days.

    Sorry to go off topic, but I've also started using paypal recently (for ebay!).

    Any idea what protection there is if someone hijacks your paypal account? - once in they would effectively have access to my bank account, which scares me a little :)

    I'm more concerned about Paypal being useless gits :evil:

    Few years back I sold something on eBay, nothing important just a pair of jeans for about a tenner. Payment received, good shipped recorded, feedback received, all happy. Month later Paypal reverse the payment but wouldn't tell me why. They implied it was often that the buyer maybe didn't have the funds afterall or was compromised etc., but I was unimpressed that their lack of ability to adequately vet a user cost me money.

    Personally, I'd trust my bank far more than Paypal as a result.
    Rose Xeon CW Disc
    CAAD12 Disc
    Condor Tempo
  • men1pal
    men1pal Posts: 29
    Sorry to go off topic, but I've also started using paypal recently (for ebay!).

    Any idea what protection there is if someone hijacks your paypal account? - once in they would effectively have access to my bank account, which scares me a little

    My paypal account got hacked about 3 years ago. Dont know how but paypal were the ones who alerted me to it. They immediately reversed the transactions before they came out of my account and then suspended my account and notified me. I then had to call them up and spend 15 minutes on the phone whilst they 'educated' me in how to stay secure. They also advised me to set up a security key which you might also find gives you extra piece of mind. Basically if you go to profile and then my account (i think) you can register your mobile as a security key. Then everytime you log in they text you a unique 6 digit code you have to enter to proceed. You can turn this on and off as much as you like from your profile and if you ever haven't got your mobile you can bypass this step by answering 3 security questions. So even if someone ever did get your username and password this way they would also need your mobile to log in and if someone else was trying to log in as you you would be notified of it as your mobile would randomly receive a text with a paypal code on it.
  • tailwindhome
    tailwindhome Posts: 19,354
    That said, I'm off to check my bank account.......

    All good.
    “New York has the haircuts, London has the trousers, but Belfast has the reason!
  • plowmar
    plowmar Posts: 1,032
    Just got hit - bank told me- after using C R C; for the two O2 debits but the bank declined a debit of £438.

    They did ring me the following morning to confirm. I've just completed the paperwork for the fraud and included the details of the article. The O2 money was back in the account before the paperwork was with me.
  • Craggers
    Craggers Posts: 185
    I got hit last week... first I knew was when I tried to use my card in tesco and it wouldn't work, rang the bank and they said they'd stopped it because of suspicious transactions...

    £15 top up to O2, £15 charity donation and a £6.50 payment to a company in america, the bank didn't let any of them go out though... top marks for them!

    And yes...I'd used CRC the week before... bugger. I was just thinking of getting some SRAM apex calipers from them as well
  • +1

    2 Top ups for £15 at o2 not long after using CRC.

    Alerted by the bank, transactions blocked, card cancelled, fraud paperwork completed and returned, new card received.

    Scumbags.
  • Worth posting a follow up:

    http://www.theregister.co.uk/2011/03/25 ... follow_up/

    Hats off to CRC for getting the experts in and actually admitting to having a problem. Also, good on The Register for being willing to go with a story that could have been seen as libellous without much in the way of obvious evidence.
  • jpm5555
    jpm5555 Posts: 56
    I also got stung for nearly 3.5K :(

    Ordered some tyres at the end of Feb with their 10 pounds off 50 pounds promotion and was stung a week later. The CC company was great and all is sorted.

    As stated, hats off to CRC for dealing with this promptly and efficiently. I believe they're offering 30 pound vouchers to victims, so I've just emailed them....
  • Levi_501
    Levi_501 Posts: 1,105
    I got hit by this, however Sanatander picked up on it straight away.

    Some company in California !
  • Fireblade96
    Fireblade96 Posts: 1,123
    Arse! Me too !
    Bought some stuff from CRC on 7/3, been hit for 3 VF topups and one o2, none of which are mine.
    Then my credit card started being rejected yesterday in Geneva airport...
    Misguided Idealist
  • tailwindhome
    tailwindhome Posts: 19,354
    *Bump*

    Turns out that I was hit for £15 on this also. Payment to 02 onh the 16th April


    I don't know if the 2 events are linked but I just got a phonecall from Santander to say that someone in 'Cricklewood'* lodged £5 into my account and then attempted to withdraw money over the counter. The cashier was suspicious and didn't hand over any cash. My account is now blocked til it's sorted out


    If you've bought from CRC you may want to double check your bank statement for susipicious transactions and foloow this up with your bank.
    “New York has the haircuts, London has the trousers, but Belfast has the reason!